Hackers are abusing the open-source Linux PRoot utility in BYOF (Bring Your Own Filesystem) attacks to provide a consistent repository of malicious tools that work across multiple Linux distributions.
Bring Your Own Filesystem (BYOF) attacks refer to when malicious individuals create a malicious filesystem on their personal devices, which stores tools often used to commit criminal activities.
Once an attacker obtains this file system, they download it and place it on their compromised machines. From there, hackers have a pre-defined set of tools at their disposal to cause even more damage to the Linux system.
Sysdig said in the report it published that these attacks usually result in cryptocurrency mining, although more harmful scenarios are possible.
The researchers also warned about how easily this new technique could be used to scale malicious actions against Linux endpoints of all kinds.

Abuse of the Linux Root utility
PRoot is an open source Linux utility that uses 'chroot', 'mount –bind' and 'binfmt_misc' to create an isolated root filesystem.
By default, PRoot processes are isolated in the guest file system – however, QEMU emulation can be used to mix host and guest program execution.
The attacks detected by Sysdig use Proot to deploy a malicious file system on already compromised systems that include network scanning tools such as “masscan” and “nmap,” the XMRig cryptominer, and their configuration files
The file system contains everything required for the attack, neatly packaged in a Gzip-compressed tar file with all necessary dependencies, dropped directly from trusted cloud hosting services, such as DropBox.

As Proot is statically compiled and requires no dependencies, threat actors simply download the precompiled binary from GitLab and execute it against the file system downloaded and extracted by the attacker to mount it.
In most cases hackers unzip the filesystem to '/tmp/Proot/' and then activate the XMRig cryptominer.

As Sysdig points out in its report, threat actors could easily use Proot to download other payloads in addition to XMRig, potentially causing more serious damage to the compromised.
The presence of “mascan” in the malicious file system indicates an aggressive stance from the attackers, likely indicating that they are planning to compromise other systems from the compromised machine.
Linux systems offer users flexibility and convenience, but they also come with an increased risk of cybersecurity threats, such as malware, rootkit attacks, DDoS attacks , and malicious code injection. Fortunately, there are steps you can take to protect yourself from these threats, such as keeping your software up to date, using strong passwords on the accounts associated with your system, using a VPN when connecting remotely, and installing antivirus software on your computer if necessary. By following these steps, you will be well on your way to creating a secure Linux environment that is less vulnerable to attacks!
Information source: bleepingcomputer.com
